Junglewise Threat Intelligence

CVE-2012-0754: Adobe Flash Player Memory Corruption Vulnerability

CVE-2012-0754 · Severity: critical · CVSS 8.1 · Exploited in the wild · Published 2022-06-08

Technologies: Adobe Flash Player, Adobe AIR. Vendors: Adobe.

Executive brief

Adobe Flash Player contains a memory corruption vulnerability (out-of-bounds write) that allows remote attackers to execute arbitrary code or cause a denial of service. The vulnerability was reported as being exploited in the wild and is included in CISA's Known Exploited Vulnerabilities Catalog.

Affected products

  • Adobe Flash Player before 10.3.183.15
  • Adobe Flash Player 11.x before 11.1.102.62
  • Adobe Flash Player before 11.1.111.6 on Android 2.x and 3.x
  • Adobe Flash Player before 11.1.115.6 on Android 4.x

Timeline

  • 2022-06-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-06-08: disclosed

Related threats